When do the DPDP security safeguards become mandatory?
Check any DPDP obligation against Rule 1 of the Digital Personal Data Protection Rules, 2025 — whether it is in force today, the date it starts, and the sub-clause that commences it.
What this obligation turns on
Rule 6 is the obligation where "not in force" is least useful as a planning answer. The seven minimum safeguards it names — encryption or tokenisation, access control, monitoring able to detect unauthorised access, backups, a year of logs, contractual terms binding processors, and measures ensuring all of it is observed rather than adopted — are a programme rather than a policy. The eighteen months Rule 1(4) allows are the build time, and an organisation treating the date as distant is measuring from the wrong end.
| Question | Answer |
|---|---|
| In force today? | No |
| Binds from | 13 May 2027 |
| Imposed by | Rule 6 — Reasonable security safeguards |
| Commenced by | Rule 1(4), “eighteen months after the date of publication of this Gazette” |
Rule 6 names seven minimum safeguards: encryption, obfuscation, masking or tokenisation; access control; logs and monitoring sufficient to detect unauthorised access; backups for continued processing; one year of log and data retention; security provisions in Data Processor contracts; and measures ensuring the safeguards are observed rather than merely adopted.
Check another obligation
The same resolution for every other duty in the Rules — the rule that imposes it, the sub-clause that commences it, and whether it binds today.
Maintaining reasonable security safeguards is imposed by rule 6, Reasonable security safeguards. Rule 1(4) commences it “eighteen months after the date of publication of this Gazette”, which is 13 May 2027, so it does not bind today and nothing under it is yet enforceable.
Rule 6 names seven minimum safeguards: encryption, obfuscation, masking or tokenisation; access control; logs and monitoring sufficient to detect unauthorised access; backups for continued processing; one year of log and data retention; security provisions in Data Processor contracts; and measures ensuring the safeguards are observed rather than merely adopted.
| Sub-clause | From | Rules | What it covers |
|---|---|---|---|
| Rule 1(2) | 13 November 2025 | 1, 2 and 17 to 21 | the definitions, and the machinery of the Data Protection Board — its appointment, its terms of service, and its functioning as a digital office |
| Rule 1(3) | 13 November 2026 | 4 | the registration and obligations of Consent Managers, and nothing else |
| Rule 1(4)Yours | 13 May 2027 | 3, 5 to 16, 22 and 23 | everything a Data Fiduciary has to do — notice, security safeguards, breach intimation, retention limits, Data Principal rights, Significant Data Fiduciary obligations and transfers outside India |
Indicative, and not legal advice. Rule 1 of the Digital Personal Data Protection Rules, 2025, notified as G.S.R. 846(E) on 13 November 2025. Whether a given obligation reaches your organisation is a determination for your legal team.
Take this away as a print-ready commencement schedule
Everything above is yours already. This is the version you can put in front of your team — the same result with your details on it, the owner columns your incident file needs, and the checklist attached. It opens here and lands in your inbox, so it is to hand when you actually need it rather than in a tab you closed.
The full commencement picture sets out all three tranches and why the notification date decides every one of them.
Rule 1 of the Digital Personal Data Protection Rules, 2025, read from MeitY’s own gazette PDF ofG.S.R. 846(E). Indicative, and not legal advice.
Every instrument cited here was verified against the issuing regulator's own notification on .Other worked examples
The same calculator, run for a specific entity — with the thresholds and clocks that apply to it, and the instrument each one comes from.
Questions this page answers
- Does the DPDP 72-hour breach notification rule apply now?
- No. Rule 7 of the Digital Personal Data Protection Rules, 2025 requires a full report to the Data Protection Board within seventy-two hours of becoming aware of a personal data breach, but Rule 1(4) commences rule 7 eighteen months after publication — 13 May 2027. Until then there is no DPDP breach-reporting duty of any length. The six-hour report to CERT-In is a separate obligation under section 70B of the IT Act 2000 and has been in force since June 2022.
- Is the DPDP Act in force in India?
- Partly. The Digital Personal Data Protection Act, 2023 and the Rules of 2025 are both notified, but commencement is phased. As at today the provisions in force are the definitions and the machinery of the Data Protection Board — its appointment, terms of service and functioning as a digital office. No obligation on a Data Fiduciary is in force until 13 May 2027, other than Consent Manager registration, which starts on 13 November 2026.
- When do DPDP penalties start?
- A penalty attaches to breaching an obligation, so it can only follow that obligation into force. The Data Protection Board provisions commenced on 13 November 2025, Consent Manager registration on 13 November 2026, and every Data Fiduciary duty on 13 May 2027. Claims that the penalty framework "applies from day one" describe a Board that exists but has no Data Fiduciary duty to adjudicate until the third tranche commences.
- When must we register as a Consent Manager?
- Rule 4 commences on 13 November 2026, one year after publication, and it is the only rule in that tranche. An organisation that is not offering Consent Manager services has no obligation on that date at all — the next date that reaches an ordinary Data Fiduciary is 13 May 2027.
- Were the DPDP Rules notified on 13 or 14 November 2025?
- The 13th. G.S.R. 846(E) is dated 13 November 2025; the 14th appears only in the e-gazette upload stamp CG-DL-E-14112025-267650 printed on the cover page. The distinction is load-bearing because Rule 1 sets commencement as an interval from publication rather than as fixed dates, so taking the 14th moves every downstream date by a day and makes "notified 14 November" and "in force 13 May 2027" mutually inconsistent.
- What DPDP obligations are in force today?
- Seven rules: rules 1 and 2, which are the short title and the definitions, and rules 17 to 21, which appoint the Chairperson and Members of the Data Protection Board, set their terms of service, govern the Board’s meetings and let it function as a digital office. All seven concern the regulator rather than the regulated. No safeguard, notice, retention or breach duty is among them.